PT-2026-104150 · WordPress · Jetformbuilder

CVE-2026-97342

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress versions prior to 3.6.5.5
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. An attacker can inject arbitrary web scripts via the wp ajax nopriv jet form builder submit endpoint. The payload is stored in post meta through the Insert/Update Post action using the choice variable. These scripts execute when a user accesses a page where the Select Field block template renders the raw meta values into option value attributes and label content via the get from db option generator.
Recommendations Update the plugin to version 3.6.5.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97342

Affected Products

Jetformbuilder